Skip to Content
ReferenceAPI & gRPC

API & gRPC Reference

All REST traffic flows API Gateway → Core Engine (orchestration) → microservices (gRPC), except Admin Console, which the gateway routes to directly. Business-logic REST controllers live almost entirely in Core Engine (60+ controller classes); Admin Console owns a separate /api/v1/admin/** namespace of its own.

REST endpoints by actor

Grouped by base path — not an exhaustive per-endpoint listing. Read the named controller for a group’s full method list.

Base pathOwning servicePurpose
/api/v1/issuer/**, /issuer/auth/**, /issuer/{issuer_did}/api-keysCore EngineIssuer auth (magic link/SSO), KYC, server-to-server API keys
/api/v1/issuers/**Core EngineIssuer portal user management; public DID/key resolution
/api/v1/portal/me/**Core EngineIssuer Portal session-scoped ops (team, credential-templates, bulk-issuance)
/api/v1/portal/catalogCore EngineIssuer-facing read view of the Program Catalog
/api/v1/credentials/**Core EngineIssue, verify, get AI insight (IssueCredentialController, VerifyCredentialController, CredentialInsightController)
/api/v1/verify/**Core EnginePublic shareable-link/QR verification — no auth
/api/v1/holder/**Core EngineHolder auth, credentials, requests, notifications, access-logs, wallet-key, consent, evidence, share links, claim flow, proof links, onboarding invites
/api/v1/holdersCore EngineHolder registry lookups
/api/v1/custodian/**Core EngineCustodian Portal: bulk intake, review/attestation, workforce compliance, search, SSO
/api/v1/custodiansCore EngineCustodian directory management
/api/v1/verifier/**Core EngineVerifier auth (self-registration, magic link)
/api/v1/verifiersCore EngineVerifier directory management
/api/v1/admin/claim-integrity, /admin/custodian-onboarding, /admin/issuer-onboarding, /admin/catalog, /admin/federated-issuers, /admin/anomaliesCore EngineCross-cutting admin ops Core Engine already orchestrates
/api/v1/admin/auth, /admin/users, /admin/config, /admin/system-health, /admin/system-logs, /admin/audit-logs, /admin/network-statsAdmin Console (own module)Platform-ops: admin-user management, config, health/log inspection
/api/v1/audit-logs, /api/v1/network-stats, /api/v1/system-healthCore EngineCross-service audit search + network stats — distinct from Admin Console’s own /api/v1/admin/* equivalents
/api/v1/reportsCore EngineCompliance exports (e.g. AVETMISS)
/api/v1/supportCore EngineLLM-backed docs support Q&A
/api/v1/demo-modeCore EngineToggle demo/seeded-data mode
/api/v1/learnersLearner Records (own REST controller)Direct REST surface — not gRPC-only

Core Engine and Admin Console both expose routes under /api/v1/admin/**, but they’re different controllers in different services, disambiguated only by sub-path — there is no shared AdminController. Check the table above before assuming which service owns a given path.

gRPC services

Proto files live in backends/shared/src/main/proto/ — 8 contracts, not the 3–4 historically documented.

Proto fileServicePortScope
credential.protoCredentialIssuanceService50051Issue/revoke/get/claim; issuer/holder/custodian listings and stats; cross-custodian LinkSupersededCredential
verification.protoVerificationEngineService50052VerifyCredential, ValidateSignature, CheckCredentialStatus, VerifyRawSignature
registry.protoIssuerRegistryService50053Issuer CRUD, DID documents, key rotation, API keys, federated-issuer trust registry
catalog.protoCatalogRegistryService50054Jurisdictions, frameworks, catalog entries/versions, code sets, regulatory schemes, scheme registrations, proposals, skills, semantic search
learner.protoLearnerRecordsService50055Learner identity, enrolments, outcomes
custodian_registry.protoCustodianRegistryService50056Custodian DID/key registry, key rotation, status, payload signing
issuer_sso.protoIssuerSsoService(Issuer Registry)Issuer SSO config, OIDC/SAML authorization + assertion validation
custodian_sso.protoCustodianSsoService(Custodian Registry)Custodian SSO config, OIDC/SAML authorization + assertion validation

Service ports

ServicegRPCREST
Credential Issuance500518081
Verification Engine500528082
Issuer Registry500538083
Program Catalog500548085
Learner Records500558086
Custodian Registry500568087
Core Engine—8080
Admin Console—8084
API Gateway—8000

There is no BatchIssue RPC anywhere in the proto contracts — batch issuance is a REST-layer concern (POST /api/v1/credentials/batch), not a streaming gRPC method.

Authentication

  1. JWT bearer tokens — API Gateway validates for issuers, holders, verifiers, custodians.
  2. Service-to-service mTLS — every internal gRPC connection requires mutual TLS with no plaintext fallback; a missing/invalid certificate fails the connection outright. See Internal gRPC mTLS.
  3. API keys — for custodial-issuer headless integrations. An issuer generates a server-to-server key via POST /api/v1/issuer/{issuer_did}/api-keys, then presents it as X-Api-Key on /api/v1/credentials/issue and /api/v1/credentials/batch instead of a JWT. See Issuer API Keys.

See API Gateway for gateway-level auth config.

Error handling

REST — standard HTTP status codes with a JSON error object:

{ "error": "CREDENTIAL_EXPIRED", "message": "The provided credential has expired and is no longer valid.", "timestamp": "2026-03-15T10:30:00Z", "correlationId": "uuid-for-tracking" }

gRPC — standard Status codes:

CodeUse case
INVALID_ARGUMENTMissing fields or malformed credential JSON
NOT_FOUNDIssuer, custodian, or credential ID not in registry
ALREADY_EXISTSDuplicate issuer/custodian registration attempt
UNAVAILABLEService (e.g. Issuer Registry) temporarily down

Rate limiting

Redis-backed, per-route (not one blanket tier), via RateLimitingGatewayFilterFactory, keyed per authenticated user/issuer or else per IP. Representative ceilings from GatewayConfig.java:

RouteLimit
Credential verify / verify-link120 req/min
Credential issue30 req/min
Issuer registration10 req/min
Issuer KYC document upload5 req/min
Credential insight / support-ask (LLM)20 req/min
Admin/portal-user/registry ops30–60 req/min

GatewayConfig is the authoritative, current per-route list — it changes independently of this page.

Versioning

  • v1 — current stable API, in active use by every route above.
  • v2 — not yet started; no v2 routes or deprecation plan exist in the codebase.